Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-2003

20
FAUCET Score

CVE-2026-2003 is a medium-severity vulnerability affecting PostgreSQL versions prior to 18.2, 17.8, 16.12, 15.16, and 14.21. It involves improper validation of the "oidvector" type, allowing an authenticated database user to disclose a few bytes of server memory. The CVSS score of 4.3 indicates a low-privilege network attack with low impact on confidentiality and no impact on integrity or availability. While the potential for disclosing confidential information is considered unlikely, the vulnerability has a FAUCET Risk Score of 73/100. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog. However, it has garnered significant community attention with 3 mentions and 3 media articles, indicating awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 14.0, < 14.21CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 15.0, < 15.16CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 16.0, < 16.12CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 17.0, < 17.8CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 18.0, < 18.2CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 26th percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (22)

beckhoffpatch availablevia llm_extracted
Fixed in: 18.2, 17.8, 16.12, 15.16, 14.21
View patch
dhis2patch availablevia llm_extracted
Fixed in: 18.2, 17.8, 16.12, 15.16, 14.21
View patch
fortinetpatch availablevia llm_extracted
Fixed in: 18.2, 17.8, 16.12, 15.16, 14.21
View patch
miniopatch availablevia llm_extracted
Fixed in: 18.2, 17.8, 16.12, 15.16, 14.21
View patch
navidromepatch availablevia llm_extracted
Fixed in: 18.2, 17.8, 16.12, 15.16, 14.21
View patch
netscoutpatch availablevia llm_extracted
Fixed in: 18.2, 17.8, 16.12, 15.16, 14.21
View patch
new_relicpatch availablevia llm_extracted
Fixed in: 18.2, 17.8, 16.12, 15.16, 14.21
View patch
nvidiapatch availablevia llm_extracted
Fixed in: 18.2, 17.8, 16.12, 15.16, 14.21
View patch
ubuntupatch availablevia ubuntu_usn
Product: postgresql-14 (jammy)Fixed in: 14.22-0ubuntu0.22.04.1
ubuntupatch availablevia ubuntu_usn
Product: postgresql-16 (noble)Fixed in: 16.13-0ubuntu0.24.04.1
ubuntupatch availablevia ubuntu_usn
Product: postgresql-17 (questing)Fixed in: 17.9-0ubuntu0.25.10.1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: postgresql16
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: postgresql
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: postgresql18
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:16/postgresql
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:15/postgresql
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:13/postgresql
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:12/postgresql
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: postgresql
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql:15/postgresql
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql:16/postgresql

Vendor Advisories (10)

ubuntuUSN-8072-1

PostgreSQL vulnerabilities

Mar 4, 2026
redhatCVE-2026-2003Moderate

postgresql: PostgreSQL oidvector discloses a few bytes of memory

Feb 12, 2026
fortinetllm-fortinet-0f3fdfbd045981fbMEDIUM

PostgreSQL oidvector discloses a few bytes of memory

Jan 1, 2026
new_relicllm-new_relic-9cc099a76accb534MEDIUM

PostgreSQL oidvector discloses a few bytes of memory

dhis2llm-dhis2-92d298dbca78b25bMEDIUM

PostgreSQL oidvector discloses a few bytes of memory

miniollm-minio-6b27864eb0587849LOW

PostgreSQL oidvector discloses a few bytes of memory

navidromellm-navidrome-4702dbbf4c5162a7MEDIUM

PostgreSQL oidvector discloses a few bytes of memory

nvidiallm-nvidia-0eaf80f1542a124bMEDIUM

PostgreSQL oidvector discloses a few bytes of memory

beckhoffllm-beckhoff-e82cb2c504e974efMEDIUM

PostgreSQL oidvector discloses a few bytes of memory

netscoutllm-netscout-b8e968257e00b91eMEDIUM

PostgreSQL oidvector discloses a few bytes of memory

References

postgresql.org / support/security/CVE-2026-2003
Vendor Advisory